// Apache Accumulo extended support

Still on Accumulo 1.10?
Both the database and the ZooKeeper under it are end of life.

Accumulo 1.10.4, released on 16 November 2023, was the final bug fix release of the 1.10 line, and the project declared 1.10 end of life with it. Accumulo 1.10 builds against ZooKeeper 3.4.14, from a line that reached end of life in June 2020. Every Accumulo release requires HDFS and ZooKeeper, so the upgrade to 2.1 touches the whole cluster. OSSeva ships patched Accumulo 1.10 and patched ZooKeeper 3.4 today, and supports the move to 2.1 when you make it.

Accumulo 1.101.9 and earlierZooKeeper 3.4.14Accumulo 2.1 LTMHDFS

Trusted globally by enterprises

Henry ScheinEnbridgeGojekMicrosoft

Why Accumulo 1.10 clusters are still running

Accumulo tends to hold data that is sensitive, large and hard to move. That is why it stays put.

The line is closed

Since 1.10.4, bugs found in 1.10 are fixed only on active release lines. The project told 1.10 users to upgrade to 2.1, its next long-term maintenance release.

ZooKeeper 3.4 is part of the package

Accumulo 1.10.4 builds against ZooKeeper 3.4.14. The 3.4 line reached end of life on 1 June 2020 and has no fix for CVE-2023-44981, the SASL quorum authentication bypass scored 9.1, which applies where SASL quorum authentication is enabled.

2.1 is a cluster upgrade, not a jar swap

Accumulo stores instance configuration, table configuration, tablet server locks and FaTE transactions in ZooKeeper. Moving to 2.1 means upgrading the ZooKeeper ensemble, the Hadoop layer and client code together, and testing iterators and permissions along the way.

The dates that matter

  1. 2020-06-01

    ZooKeeper 3.4 reaches end of life. Accumulo 1.10 builds against 3.4.14.

  2. 2023-11-16

    Accumulo 1.10.4 released as the final 1.10 bug fix release. The 1.10 line is end of life.

  3. 2026-07-17

    Accumulo 2.1.6, the current long-term maintenance release, builds against ZooKeeper 3.9.5.

  4. 2026-09-24

    Accumulo 4.0.0-alpha-1. FaTE transactions still live in ZooKeeper.

What OSSeva delivers

1

Patched Accumulo 1.10

Security fixes backported to Accumulo 1.10 and its bundled dependencies, built from upstream source and shipped as signed tarballs and Maven artifacts. Iterators, configuration and on-disk formats stay the same.

OSSeva PatchAccumulo 1.10 and earlierSigned artifacts
2

Patched ZooKeeper 3.4 underneath

Patched builds of ZooKeeper 3.4 for the ensemble Accumulo depends on, with third-party CVE attestation, including VEX, for the auditors who review the cluster.

OSSeva PatchZooKeeper 3.4.14VEX attestation
3

Upgrade to 2.1 and cluster operations

A tested upgrade path to Accumulo 2.1 with the ZooKeeper and Hadoop layers moved in the right order, and 24/7 operations for the cluster if you want them.

OSSeva Assure1.10 to 2.1OSSeva Operate

Your options, compared

OptionWhat you getTrade-off
Upgrade to Accumulo 2.1The current long-term maintenance line and a supported ZooKeeper clientA coordinated upgrade of Accumulo, ZooKeeper and Hadoop, with client and iterator testing.
Move to Accumulo 3.0A newer release line3.0 is not a long-term maintenance release, so another upgrade follows.
OSSeva extended supportPatched Accumulo 1.10 and ZooKeeper 3.4, and an upgrade pathA subscription while you plan the upgrade.
Stay unpatchedNothingEvery advisory since November 2023 stays open on a store of sensitive data.

End-of-life status from the Accumulo 1.10.4 release notes. Release lines from accumulo.apache.org/downloads and the Accumulo versioning page. Bundled ZooKeeper versions from pom.xml at the rel/1.10.4, rel/2.1.6 and rel/3.0.0 tags. ZooKeeper dates and CVE ranges from zookeeper.apache.org and NVD.

Frequently asked questions

Is Accumulo 1.10 end of life?

Yes. Accumulo 1.10.4, released on 16 November 2023, was the final 1.10 bug fix release, and the project declared the 1.10 line end of life with it.

Which ZooKeeper does Accumulo 1.10 use?

Accumulo 1.10.4 builds against ZooKeeper 3.4.14. The ZooKeeper 3.4 line reached end of life on 1 June 2020.

What should Accumulo 1.10 users upgrade to?

The project points to 2.1, its long-term maintenance line. 2.1.6, released on 17 July 2026, builds against ZooKeeper 3.9.5.

Can Accumulo run without ZooKeeper?

No. Every Accumulo release requires HDFS and ZooKeeper, and even the 4.0 alpha keeps FaTE transactions in ZooKeeper.

Keep Accumulo 1.10 patched until 2.1 is ready.

Talk to an engineer about your Accumulo cluster, its ZooKeeper and its Hadoop layer.